Confused by 26.7 upgrade

Started by Plethodon, August 31, 2026, 12:29:18 AM

Previous topic - Next topic
> Apparently the rules didn't continue to work.

You're convoluting your experience with the technical facts in this particular case. It's futile to go into an argument like that.


Cheers,
Franco

Today at 05:05:58 AM #31 Last Edit: Today at 05:24:10 AM by defaultuserfoo
Quote from: franco on September 08, 2026, 08:56:50 AM> Apparently the rules didn't continue to work.

You're convoluting your experience with the technical facts in this particular case. It's futile to go into an argument like that.


Cheers,
Franco

I'm not convoluting anything.  IIUC, someone created this thread when he found that he can not enable or disable firewall rules after an upgrade anymore, and was advised to install a plug-in to fix that.  I haven't made this experience, but I made the experience that the firewall rules didn't work after the migration and had all to be redone.  After the painful experience, I was told that it would take many years to come before the migration would be necessary.  In spite of that, now apparently everyone who wants to be able to enable or disable firewall rules needs to do some kind of migration, even if it is only to install the plug-in.

Don't continue to pretend that it is an easy and harmless migration that wouldn't even require a big fat warning.  It is not.

This is not about technical details but about the user experience and about improving it.  From the technical details being clear to the developers, it doesn't follow that users are sufficiently informed even when they read the release notes.  Apparently, this very argument is futile here.  I wonder why that is.
PowerEdge R210II

Regarding the specific topic at hand: The transition to the new rule framework has been a subject of discussion in this forum since January 2026. The migration assistant is a no-brainer; thanks to it—and the available backup and restore options—the transition poses absolutely no risk.

In general, users of the OPNsense Community Edition should be aware that they are, to some extent, testers for new features that eventually make their way into the paid version of OPNsense.
In return, however, they receive a fantastic firewall for free—one that need not shy away from comparison with expensive commercial competitors.
This forum is active and monitored by highly experienced users who are always ready to help—often even when a topic has been discussed repeatedly and the answer could have been found via a simple search.

It is up to the individual whether to adopt changes early during version updates or to wait for reliable, rapid bug fixes.
However, if you use the Community Edition, I believe you also bear some responsibility for regularly reading forum posts; otherwise, you might find yourself facing a problem eight months down the line that has already been thoroughly discussed and addressed. This applies equally to experienced forum members and OPNsense newcomers.
Supermicro M11SDV-4C-LN4F AMD EPYC 3151 4x 2.7GHz RAM 8GB DDR4-2666 SSD 250GB

A great example is the Intel microcode plugin that if I had read the forum properly would have known I should have removed it before upgrading to 26.7.
I didn't, so I had a broken install since it timed out trying to upgrade and I had to use the bootstrap script to fix it.

> IIUC, someone created this thread when he found that he can not enable or disable firewall rules after an upgrade anymore, and was advised to install a plug-in to fix that.

Which is correct, but that's in the release notes. You don't need the plugin to use and/or migrate the rules, but you need the plugin to administrate them.

> but I made the experience that the firewall rules didn't work after the migration and had all to be redone

Which is entirely different.  It may be because of FreeBSD 15.1 or something else.  It looks like we don't know?

> Don't continue to pretend that it is an easy and harmless migration that wouldn't even require a big fat warning.  It is not.

I never pretended it was easy and harmless for you.  This is the core of the issue.  It is your experience.  Not everyone else's.

> I wonder why that is.

Because you don't know what the problem is, but feel entitled to raise your concern in advance?  If I know your exact problem I can probably help or point to the right bits of documentation.

> However, if you use the Community Edition, I believe you also bear some responsibility for regularly reading forum posts; otherwise, you might find yourself facing a problem eight months down the line that has already been thoroughly discussed and addressed. This applies equally to experienced forum members and OPNsense newcomers.

Sometimes perhaps, but I'm surprised at the trivial questions that are being raised seeing the code that was touched and people not realising how many technical issues they would never notice because a) they don't have the setup or b) changes are handled in a way that few regressions arise to begin with.

> A great example is the Intel microcode plugin that if I had read the forum properly would have known I should have removed it before upgrading to 26.7.

It's a very complex issue involving the microcode updates and the operating system that has been going on for years now -- and both are not under our immediate influence.  And here, also, it was clearly in the release notes:

https://github.com/opnsense/changelog/blob/b0be678d6235cb8da05446df7ea233c38cdcd0a7/community/26.7/26.7#L101


Cheers,
Franco